vulnerability

RHSA-2016:0007: nss security update

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
2016-01-07
Added
2016-01-08
Modified
2017-10-30

Description

Network Security Services (NSS) is a set of libraries designed to supportthe cross-platform development of security-enabled client and serverapplications.A flaw was found in the way TLS 1.2 could use the MD5 hash function forsigning ServerKeyExchange and Client Authentication packets during a TLShandshake. A man-in-the-middle attacker able to force a TLS connection touse the MD5 hash function could use this flaw to conduct collision attacksto impersonate a TLS server or an authenticated TLS client. (CVE-2015-7575)All nss users are advised to upgrade to these updated packages, whichcontain a backported patch to correct this issue. For the update to takeeffect, all services linked to the NSS library must be restarted, or thesystem rebooted.

Solution(s)

redhat-upgrade-nssredhat-upgrade-nss-debuginforedhat-upgrade-nss-develredhat-upgrade-nss-pkcs11-develredhat-upgrade-nss-sysinitredhat-upgrade-nss-tools
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.